# CORS issue with socketIO

**URL:** <https://discuss.konghq.com/t/cors-issue-with-socketio/3480>\
**Category:** Questions\
**Created:** [May 9, 2019, 7:57pm UTC](https://discuss.konghq.com/t/cors-issue-with-socketio/3480 "2019-05-09T19:57:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![keirankozlowski](https://avatars.discourse-cdn.com/v4/letter/k/848f3c/32.png) [@keirankozlowski](https://discuss.konghq.com/u/keirankozlowski)\
**Post date:** [May 9, 2019, 7:57pm UTC](https://discuss.konghq.com/t/cors-issue-with-socketio/3480/1 "2019-05-09T19:57:04Z")

</div>

I’m having an issue where I receive the following CORS message when attempting to connect to our socketio websocket, but not with regular API requests. Not having this issue when pointing to our non-Kong test server. I do also have the Kong CORS plugin installed and configured on this service.

`Access to XMLHttpRequest at 'url' from origin 'http://localhost:4200' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: The value of the 'Access-Control-Allow-Origin' header in the response must not be the wildcard '*' when the request's credentials mode is 'include'. The credentials mode of requests initiated by the XMLHttpRequest is controlled by the withCredentials attribute.`

I’ve tried passing specific corsOptions to send different info with that header in our Node backend but that doesn’t seem to resolve. Any ideas?

---

<div class="post-metadata">

**Author:** ![jeremyjpj0916](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jeremyjpj0916/32/1388_2.png) [@jeremyjpj0916](https://discuss.konghq.com/u/jeremyjpj0916)\
**Post date:** [May 9, 2019, 8:40pm UTC](https://discuss.konghq.com/t/cors-issue-with-socketio/3480/2 "2019-05-09T20:40:51Z")

</div>

> [@keirankozlowski](#):
>
> [http://localhost:4200](http://localhost:4200)

Would adding [http://localhost](http://localhost) as opposed to \* fix the cors origin list setting on the plugin for your preflight exception error you are getting most likely?

---

<div class="post-metadata">

**Author:** ![keirankozlowski](https://avatars.discourse-cdn.com/v4/letter/k/848f3c/32.png) [@keirankozlowski](https://discuss.konghq.com/u/keirankozlowski)\
**Post date:** [May 10, 2019, 6:59pm UTC](https://discuss.konghq.com/t/cors-issue-with-socketio/3480/3 "2019-05-10T18:59:48Z")

</div>

I’ve tried that as well. ☹

---

<div class="post-metadata">

**Author:** ![jeremyjpj0916](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jeremyjpj0916/32/1388_2.png) [@jeremyjpj0916](https://discuss.konghq.com/u/jeremyjpj0916)\
**Post date:** [May 10, 2019, 8:41pm UTC](https://discuss.konghq.com/t/cors-issue-with-socketio/3480/4 "2019-05-10T20:41:49Z")

</div>

I keep comming back to seeing this error you mention:

The value of the ‘Access-Control-Allow-Origin’ header in the response must not be the wildcard ‘\*’ when the request’s credentials mode is ‘include’.

So be sure to remove the \* from your cors origins list too if you have not tried that, also if its just complaining about the credentials mode is included i wonder if disabling the creds Boolean config option would possibly help too? Maybe post the CORS plugin settings you have tried with and the various errors each one gets here.

---

<div class="post-metadata">

**Author:** ![rony.tampubolon](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/rony.tampubolon/32/1853_2.png) [@rony.tampubolon](https://discuss.konghq.com/u/rony.tampubolon)\
**Post date:** [April 13, 2020, 2:04pm UTC](https://discuss.konghq.com/t/cors-issue-with-socketio/3480/5 "2020-04-13T14:04:57Z")

</div>

Is there any step how to setup cors in Route in Kong Community 2.0.x ?  
Just setup cors plugin on route but still return _has been blocked by CORS policy: Response to preflight request doesn’t pass access control check: No ‘Access-Control-Allow-Origin’ header is present on the requested resource_  
any help @jeremyjpj0916?
